CVE-2020-3191
published 2020-05-06CVE-2020-3191: A vulnerability in DNS over IPv6 packet processing for Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow…
PriorityP349high8.6CVSS 3.1
AVNACLPRNUINSCCNINAH
EPSS
1.82%
76.3th percentile
A vulnerability in DNS over IPv6 packet processing for Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to unexpectedly reload, resulting in a denial of service (DoS) condition. The vulnerability is due to improper length validation of a field in an IPv6 DNS packet. An attacker could exploit this vulnerability by sending a crafted DNS query over IPv6, which traverses the affected device. An exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. This vulnerability is specific to DNS over IPv6 traffic only.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance_software | >= 9.10 < 9.10.1.37 | 9.10.1.37 |
| cisco | adaptive_security_appliance_software | >= 9.12 < 9.12.2.9 | 9.12.2.9 |
| cisco | adaptive_security_appliance_software | >= 9.6 < 9.6.4.36 | 9.6.4.36 |
| cisco | adaptive_security_appliance_software | >= 9.8 < 9.8.4.12 | 9.8.4.12 |
| cisco | adaptive_security_appliance_software | >= 9.9 < 9.9.2.66 | 9.9.2.66 |
| cisco | asa_5505_firmware | — | — |
| cisco | asa_5505_firmware | — | — |
| cisco | asa_5510_firmware | — | — |
| cisco | asa_5510_firmware | — | — |
| cisco | asa_5512-x_firmware | — | — |
| cisco | asa_5512-x_firmware | — | — |
| cisco | asa_5515-x_firmware | — | — |
| cisco | asa_5515-x_firmware | — | — |
| cisco | asa_5520_firmware | — | — |
| cisco | asa_5520_firmware | — | — |
| cisco | asa_5525-x_firmware | — | — |
| cisco | asa_5525-x_firmware | — | — |
| cisco | asa_5540_firmware | — | — |
| cisco | asa_5540_firmware | — | — |
| cisco | asa_5545-x_firmware | — | — |
| cisco | asa_5545-x_firmware | — | — |
| cisco | asa_5550_firmware | — | — |
| cisco | asa_5550_firmware | — | — |
| cisco | asa_5555-x_firmware | — | — |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv3.08.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software IPv6 DNS Denial of Service Vulnerability
vendor_cisco·2020-05-06·CVSS 8.6
CVE-2020-3191 [HIGH] CWE-20 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software IPv6 DNS Denial of Service Vulnerability
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software IPv6 DNS Denial of Service Vulnerability
A vulnerability in DNS over IPv6 packet processing for Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to unexpectedly reload, resulting in a denial of service (DoS) condition.
The vulnerability is due to improper length validation of a field in an IPv6 DNS packet. An attacker could exploit this vulnerability by sending a crafted DNS query over IPv6, which traverses the affected device. An exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. This vulnerability is specific to DNS over IPv6 traffic only.
Cisco has rele
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software IPv6 DNS Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3191 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software IPv6 DNS Denial of Service Vulnerability
CVE-2020-3191: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software IPv6 DNS Denial of Service Vulnerability
A vulnerability in DNS over IPv6 packet processing for Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to unexpectedly reload, resulting in a denial of service (DoS) condition. The vulnerability is due to improper length validation of a field in an IPv6 DNS packet. An attacker could exploit this vulnerability by sending a crafted DNS query over IPv6, which traverses the affected device. An exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. This vulnerability is specific to DNS over IPv6 traffic only. C
GHSA
GHSA-54hx-xv6r-c55r: A vulnerability in DNS over IPv6 packet processing for Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software co
ghsa_unreviewed·2022-05-24
CVE-2020-3191 [MEDIUM] CWE-20 GHSA-54hx-xv6r-c55r: A vulnerability in DNS over IPv6 packet processing for Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software co
A vulnerability in DNS over IPv6 packet processing for Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to unexpectedly reload, resulting in a denial of service (DoS) condition. The vulnerability is due to improper length validation of a field in an IPv6 DNS packet. An attacker could exploit this vulnerability by sending a crafted DNS query over IPv6, which traverses the affected device. An exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. This vulnerability is specific to DNS over IPv6 traffic only.
No detection rules found.
No public exploits indexed.
Tenable
Cisco Patches Multiple Flaws in Adaptive Security Appliance and Firepower Threat Defense (CVE-2020-3187)
blogs_tenable·2020-05-07·CVSS 9.1
[CRITICAL] Cisco Patches Multiple Flaws in Adaptive Security Appliance and Firepower Threat Defense (CVE-2020-3187)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2020-7106 cacti: XSS due to lack of escaping on some pages
bugzilla·2020-01-29·CVSS 6.1
CVE-2020-7106 [MEDIUM] CVE-2020-7106 cacti: XSS due to lack of escaping on some pages
CVE-2020-7106 cacti: XSS due to lack of escaping on some pages
Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is displayed by $header to trigger the XSS).
Reference:
https://github.com/Cacti/cacti/issues/3191
Discussion:
Created cacti tracking bugs for this issue:
Affects: epel-6 [bug 1796209]
2020-05-06
Published